Known vulnerabilities in the Amp plugin
9 security advisories have been published for the Amp plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Amp - Arbitrary File Upload (CVE-2026-9067) CRITICAL
- Amp - Cross-Site Scripting (XSS) (CVE-2025-14069) MEDIUM
- Amp - Cross-Site Scripting (XSS) (CVE-2025-11502) MEDIUM
- Amp - Cross-Site Scripting (XSS) (CVE-2025-9512) MEDIUM
- Amp - Cross-Site Scripting (XSS) (CVE-2024-5582) MEDIUM
- Amp - Cross-Site Scripting (XSS) (CVE-2024-3491) MEDIUM
- Amp - Cross-Site Scripting (XSS) (CVE-2024-1586) MEDIUM
- Amp - Broken Access Control (CVE-2024-1288) MEDIUM
- Amp - Broken Access Control (CVE-2021-4366) MEDIUM